{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/beaconing/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Elastic Defend","Fleet","Network Beaconing Identification integration"],"_cs_severities":["low"],"_cs_tags":["command-and-control","beaconing","network-detection","endpoint-security","machine-learning"],"_cs_type":"advisory","_cs_vendors":["Elastic"],"content_html":"\u003cp\u003eThis brief describes a detection capability from Elastic Security designed to identify command-and-control (C2) beaconing activity. The detection relies on a statistical model that analyzes network logs to pinpoint periodic, stealthy communication patterns indicative of C2. C2 beaconing allows attackers to maintain covert communication channels with compromised systems, receive instructions, deliver additional payloads, exfiltrate sensitive data, and ensure persistence within a network. The rule specifically targets the output of Elastic's Network Beaconing Identification integration, which processes network events collected by the Elastic Defend integration from both Windows and Linux endpoints. It intelligently filters out known benign processes like \u003ccode\u003emetricbeat.exe\u003c/code\u003e, \u003ccode\u003eMsMpEng.exe\u003c/code\u003e, \u003ccode\u003eOUTLOOK.EXE\u003c/code\u003e, and \u003ccode\u003ednf\u003c/code\u003e to reduce false positives and focus on genuinely anomalous behavior. This detection capability is crucial for identifying sophisticated post-exploitation activities often associated with various threat actors.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003cp\u003eThis brief describes a detection mechanism for command-and-control (C2) beaconing, which is a post-compromise activity. It does not detail a specific attack chain from initial access through impact, as the focus is on the detection of the C2 communication behavior itself rather than the full sequence of an adversary's actions. The beaconing activity typically occurs after initial access has been gained and malware has been deployed, serving to maintain persistent communication between the compromised host and the attacker's C2 infrastructure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful C2 beaconing enables adversaries to maintain long-term unauthorized access to compromised systems and networks. This can lead to various severe impacts including persistent data exfiltration of sensitive information, deployment of additional malicious payloads (e.g., ransomware), lateral movement across the network, and establishment of backdoors for future access. The stealthy nature of beaconing, by mimicking legitimate traffic patterns, allows attackers to operate undetected for extended periods, maximizing the potential for damage and intellectual property theft. The specific number of victims and sectors targeted can vary widely depending on the adversary and their objectives, but the underlying capability of sustained C2 communication significantly elevates the risk of profound financial, reputational, and operational damage.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the Network Beaconing Identification integration and Elastic Defend to collect the necessary \u003ccode\u003eml_beaconing.all\u003c/code\u003e log data for this detection.\u003c/li\u003e\n\u003cli\u003eMonitor alerts generated by the \u0026quot;Statistical Model Detected C2 Beaconing Activity\u0026quot; rule in your Elastic Security environment for potential C2 communications.\u003c/li\u003e\n\u003cli\u003eInvestigate network traffic logs and associated processes for any alerts, cross-referencing IP addresses with threat intelligence as part of your incident response process.\u003c/li\u003e\n\u003cli\u003eRegularly review and update the list of excluded \u003ccode\u003eprocess.name\u003c/code\u003e values in the rule's query to minimize false positives arising from legitimate applications that exhibit periodic network communication.\u003c/li\u003e\n\u003cli\u003eIsolate systems identified with C2 beaconing activity to prevent further communication and conduct a thorough forensic analysis and malware scan.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-28T18:00:34Z","date_published":"2026-07-27T15:26:08Z","id":"https://feed.craftedsignal.io/briefs/2026-07-c2-beaconing-detection/","summary":"Elastic Security's statistical model identifies command-and-control (C2) beaconing activity in network logs on Windows and Linux systems by analyzing network traffic patterns and excluding known benign processes, enabling defenders to detect and respond to stealthy adversary communications for persistence and data exfiltration.","title":"Statistical Model Detected Command-and-Control Beaconing Activity","url":"https://feed.craftedsignal.io/briefs/2026-07-c2-beaconing-detection/"}],"language":"en","title":"CraftedSignal Threat Feed - Beaconing","version":"https://jsonfeed.org/version/1.1"}